Medium
GuardDuty
Regional
GuardDuty ECS Runtime Monitoring should be enabled
FSBP
Description
Verifies that the GuardDuty automated security agent is enabled for runtime monitoring of ECS clusters on AWS Fargate in all accounts.
Remediation
To enable GuardDuty ECS Runtime Monitoring, you need to configure the ECS Runtime Monitoring settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'Runtime Monitoring'
- Enable 'ECS Runtime Monitoring' for Fargate
- Configure security agents for ECS clusters
- Set up monitoring for ECS tasks on Fargate
- Save the configuration
- Verify that ECS Runtime Monitoring is active
Compliance
FSBP